Windows error on startup (details inside)

Maybe someone can help me? this doesnt happen frequently but it happens prob 1 out of every 10 times and it happens when I start up my computer and my internet cable isnt plugged in and the error comes from these two

C:DOCUME~1\user\LOCALS~1\Temp\WER9077.dir00\svchost.exe.mdmp
C:DOCUME~1\user\LOCALS~1\Temp\WER9077.dir00\appcompat.txt

If I have my cable in it doesnt seem to hurt it…

Im running Windows XP with SP2 and fully updated

What happens?

Did you try to scan these files?
Did you try to delete this temporary files?

What happens is I get a Windows popup telling me of the error. Ive submitted the info to Microsoft everytime but it only seems to happen when I dont have my net cable plugged in :confused:

The obvious simple solution is to make sure your cable is plugged in.
Your getting an error because something is trying to access the net and it can’t.

But is it legitimate?
It’s strange for me… Are you sure you’re not infected or hijacked?

parachutestx
Maybe you should check out the following link:
http://www.updatexp.com/msblast-exe.html

Trust me Bob its not the Blaster worm lol and yes Im not hijacked I scan my computer least 3 times a day. I have Zone Alarm which although its good Ive heard there is conflict with other programs ?

also that SVChost is part of the windows system and ive watched as it boots up and the thing that usually pops up is ISAFE which is part of Zonealarm.

I think it just gives me the error when my cable is not connected saying ess hey I need to connect but there is no connection.

that and im on a Gateway which does suck ass if you pardon my french.

Does the Windows Event Log provide any information, could you post it? Windows usually tries to identify the error module.

What were the contents of the appcompat.txt file?

Trust me Bob its not the Blaster worm lol and yes Im not hijacked I scan my computer least 3 times a day. I have Zone Alarm which although its good Ive heard there is conflict with other programs ?

Use HijackThis to scan your computer. ZoneAlarm doesn’t scan your computer, it scans your incoming and outgoing ports… certainly doesn’t scan of spyware, adware and browser hijackers. That’s why we use Spybot Search&Destroy, Ad-Aware by Lavasoft and Bazooka Spyware Scanner (to give you instructions on how to clean those things).

Your cable plugged in or not, Windows shouldn’t give you any warning, especially not those minidumps… If I unplug my cable, nothing happens except I’m not connected to the internet… but, that’s my problem, not something that Windows should worry about, unless I’m trying to access internet and then, Windows should inform you that you are not connected…

As I said, use HijackThis ( Link: http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/HijackThis.shtml ) and post your log file in here…

Cheers !

Logfile of HijackThis v1.99.1
Scan saved at 3:06:31 PM, on 4/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\ZoneLabs\isafe.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN\MSNCoreFiles\MSN6.EXE
C:\DOCUME~1\user\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

O4 - HKLM..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,BluetoothAuthenticationAgent
O4 - HKLM..\Run: [Zone Labs Client] “C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe”
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM..\Run: [nwiz] nwiz.exe /install
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I think I found what’s causing your problem…

The weird thing is that as soon as I analyzed your log file, I’ve noticed isafe.exe

isafe.exe is a part of Computer Associates eTrust AntiVirus which keeps your Internet security product upto date. It’s also used by ZoneLabs internet security, but I don’t kow much about that process…

It looks like it’s always trying to connect to the internet in order to update your eTrust Antivirus. Worst of all, is… that, to me, it looks like you have two antiviruses installed on the same computer in the same time… no good at all. Maybe I’m wrong, but just in case, I wanna check that with you first…

If you don’t use eTrust antivirus, make sure to completely uninstall that application because all you’ll get with 2 antiviruses running on your system, are additional headaches and problems… believe me, avast! is enough. :wink: On the other hand, if that process is part of ZoneLabs internet security (I run ZoneAlarm and I don’t have it), than again… you have 2 antiviruses installed, because I believe that ZoneLabs are offering antivirus as well…

Never ever install 2 or more antivirus programs with resident shield enabled on the same machine in the same time…

Cheers !

parachutestx
The only other items that should be checked out is the following:

C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
This could be either good or bad. Please see the following link: [url]http://www.auditmypc.com/process/viewmgr.asp[/url]

Yes, Bob is right… in HijackThis log File analyzer it’s characterized as SAFE, but it could be that it’s trying to access the internet searching for those updates… If I was you, I would check that too…

Cheers !